PT-2026-50244 · Undefined · Undefined
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LearnPress versions prior to 4.3.7
Description
An information disclosure issue exists where the
edit context on a REST endpoint is not properly restricted by the edit users capability. This allows unauthenticated visitors to retrieve sensitive user data, including roles, full capabilities map, extra capabilities, locale, and registration date, by sending a crafted request.Recommendations
Update LearnPress to version 4.3.7 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined